Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 09 April

Monthly Patches are out for SAP, Siemens, Schneider Electric and Unisoc. New Alert for Welotec. Monthly Patches for Microsoft, Adobe, and Node.js are expected this afternoon. SAP  SAP Security Patch Day saw the release of 10 new Security Notes and 2 updated Security Notes. Highest CVSSv3 score of 8.8More info. Siemens  Siemens Monthly Pat...

0
  638 Hits

New Vulnerabilities Monday 08 April

New Alerts for FRRouting, Westermo, Dell, and OpenSSL. FRRouting  In FRRouting a remote attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash. CVSSv3 score of 7.5More info. Westermo  WeOS uses the WebDAV PROPFIND and could allow a remote attacker to obtain sensitive information. CVSSv3 s...

0
  546 Hits

New Vulnerabilities Friday 05 April

New Alerts for Brocade, Apache, Dell, BD, Microsoft Edge, and NetApp. Brocade  An RCE vulnerability in Brocade Fabric OS could allow a remote attacker to execute arbitrary code and use this to gain root access to the switch. CVSSv3 score of 8.6More info. Apache  Apache has updated HTTP Server to fix several security vulnerabilities, inclu...

0
  652 Hits

New Vulnerabilities Thursday 04 April

New Alerts for Cisco, HTTP/2, Ivanti, ABB, HPE, Lexmark, and Linux. Cisco  Cisco has published 12 new bulletins, 1 rated High and the rest Medium. Highest CVSSv3 score of 7.5More info.A vulnerability in the OOB PnP feature of Cisco Nexus Dashboard Fabric Controller could allow a remote attacker to read arbitrary files. CVSSv3 score of 7.5More ...

0
  531 Hits

New Vulnerabilities Wednesday 03 April

Monthly Patches are out for Google Pixel. New Alerts for VMware, Supermicro, Google Chrome, Hitachi, TRENDnet, NetApp, and Linux. VMware  Multiple vulnerabilities have been fixed in VMware SD-WAN. Highest CVSSv3 score of 7.4More info. Supermicro  Three security issues have been discovered in select Supermicro motherboards. Highest CVSSv3 ...

0
  536 Hits

New Vulnerabilities Tuesday 02 April

Monthly Patches are out for Google Android and Samsung. New Alerts for IBM and Linux. Google  Android Monthly Patches are out, with 8 vulnerabilities, all rated High, plus MediaTek, Widevine, and Qualcomm patches.More info. Samsung  Samsung Monthly Patches for Mobile are out, with Android patches and 17 additional Samsung vulnerabilities....

0
  617 Hits

New Vulnerabilities Monday 01 April

Monthly Patches are out for Qualcomm and MediaTek. A backdoor has been discovered in XZ Utils. New Alerts for Eaton, Microsoft Edge, Dell, and HPE. XZ Utils Exploit A backdoor has been installed XZ Utils. It was discovered before it made its way into most Linux distributions and its impact should be limited. CVSSv3 score of 10.More info. And here. ...

0
  688 Hits

New Vulnerabilities Friday 29 March

New Alerts for Dell, F5, and NetApp. Dell  PowerScale OneFS, Power Protect Data Manager, PowerMaxOS, PowerMax OS, Unisphere 360, Unisphere for PowerMax, Unisphere for PowerMax vApp, Solutions Enabler vApp, and Dell PowerMax EEM all have remediation available for multiple security vulnerabilities in third-party software. Dell rates these Critic...

0
  631 Hits

New Vulnerabilities Thursday 28 March

New Alerts for Cisco, Splunk, NVIDIA, Microsoft Edge (Exploit), IBM, DrayTek, Wireshark, and Linux. Cisco  Cisco has published 17 new bulletins, 10 rated High and 7 rated Medium. Highest CVSSv3 score of 8.6More info.A vulnerability in the LISP feature of IOS Software and IOS XE Software could allow a remote attacker to cause an affected device...

0
  554 Hits

New Vulnerabilities Wednesday 27 March

New Alerts for Google Chrome, AutomationDirect, Hitachi Energy, Dell, HPE, curl, an Linux. Google  Google has updated Chrome for Desktop to fix 7 security vulnerabilities, at least 1 rated Critical.More info.Microsoft is aware. More info. AutomationDirect  C-MORE EA9 HMI contains several vulnerabilities, including Path Traversal, Stack-Ba...

0
  576 Hits

New Vulnerabilities Tuesday 26 March

New Alerts for Apple, BD, IBM, Kaspersky, Tenable, and Linux. Apple  Apple has published security updates for macOS and Safari, as well as provided details for last week's iOS, iPadOS, and VisionOS bulletins.More info. BD  BD has published security updates to fix third-party software for IDM, Data Agent, Pyxis, CCE, and Alaris.More info. ...

0
  558 Hits

New Vulnerabilities Monday 25 March

New Alerts for Microsoft Edge, F5, NetApp, and Linux. Microsoft  Microsoft has updated Edge to fix 2 Edge-specific vulnerabilities and include the latest chromium updates.More info. F5  BIG-IP and BIG-IQ contain a vulnerable version of Bind that could result in a DoS. CVSSv3 score of 7.5More info. NetApp  NetApp has published 8 bulle...

0
  640 Hits

New Vulnerabilities Friday 22 March

New Alerts for Honeywell, Rockwell Automation, Apple, Mozilla, and Linux. Honeywell  XSS / Arbitrary Code Injection vulnerabilities exist in Honeywell MPA2. Highest CVSSv3 score of 8.1More info. Rockwell Automation  A DoS vulnerability exists in the PowerFlex 527 due to improper input validation in the device. If exploited, the web server...

0
  561 Hits

New Vulnerabilities Thursday 21 March

New Alerts for HP, F5, IBM, Dell, BD, and Linux. HP  HP OfficeJet Pro printers are vulnerable to a DoS when using an improper eSCL URL GET request. CVSSv3 score of 6.5More info. F5  Traffix SDC contains a vulnerability that allows a remote attacker to cause a DoS. CVSSv3 score of 6.5More info. IBM  IBM Spectrum Protect Plus can be af...

0
  552 Hits

New Vulnerabilities Wednesday 20 March

New Alerts for Franklin Electric Fueling Systems, Google Chrome, Atlassian, Dell, and Linux. Franklin Electric  Franklin Fueling System EVO 550, EVO 5000 contains a Path Traversal vulnerability that could allow a remote attacker to read arbitrary files on the system. Highest CVSSv3 score of 8.7More info. Google  Google has updated Chrome ...

0
  541 Hits

New Vulnerabilities Tuesday 19 March

New Alerts for IBM, Mozilla, Acronis, Dell, and Linux. IBM  IBM App Connect Enterprise is vulnerable to a remote attacker due to node.js IP package. CVSSv3 score of 9.8More info. Mozilla  Mozilla has published updates for Firefox, Firefox ESR, and Thunderbird, all rated High.More info. Acronis  Acronis Cyber Protect Cloud Agent has b...

0
  585 Hits

New Vulnerabilities Monday 18 March

New Alerts for IBM, PaperCut, Canon, and Linux. IBM  IBM Cloud Pak for Data Scheduling contains vulnerable third-party software packages. Highest CVSSv3 score of 9.8More info. And here. PaperCut  The Monthly Security Bulletin is out for PaperCut NG/MF. Highest CVSSv3 score of 8.6More info. Canon  A potential buffer overflow vulnerabi...

0
  712 Hits

New Vulnerabilities Friday 15 March

New Alerts for Juniper, Microsoft Edge, Dell, HPE, NetApp, Mitel, and Linux. Juniper  Multiple vulnerabilities have been resolved in Juniper Secure Analytics. Highest CVSSv3 score of 9.8More info. Microsoft  Microsoft has updated Edge to fix chromium-based vulnerabilities as well as 3 Edge-specific vulnerabilities.More info. Dell  De...

0
  619 Hits

New Vulnerabilities Thursday 14 March

New Alerts for Cisco, Arcserve, Apache Tomcat, BD, Mitsubishi Electric, IBM, and Linux. Cisco  Cisco has published 7 new security bulletins. Highest CVSSv3 score of 7.8.More info. A vulnerability in theDHCPv4 server feature of IOS XR Software could allow a remote attacker to trigger a crash of the dhcpd process, resulting in a DoS. CVSSv3 scor...

0
  655 Hits

New Vulnerabilities Wednesday 13 March

Monthly Patches are out for Microsoft, Adobe, and Fortinet. New Alerts for Google Chrome, Bosch, Citrix, Hitachi, IBM, Intel, and Linux. Tomorrow may be Palo Alto Monthly Patches. Microsoft  Microsoft Monthly Patches include 61 vulnerabilities. Two are rated Critical. Highest CVSSv3 score of 9.8More info. And here. Adobe  Adobe Monthly Pa...

0
  575 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/